Home Projects Blog Wiki Support About Contact
  

The Sleuth Kit
     
File Systems
     
Plug-in Framework
     
Download
     
Documents
     
History
     
Licenses
  

Autopsy
  

Sleuth Kit Hadoop
  

mac-robber
  

Case Studies
  




Get The Sleuth Kit at SourceForge.net. Fast, secure and Free Open Source software downloads

Download

There are three different packages for each TSK release.

  • sleuthkit-X.X.X.tar.gz: This is the source code release of TSK core and framework that you must compile on your computer. This is most commonly used on non-windows systems.
  • sleuthkit-X.X.X-win32.zip: This is the compiled windows release of TSK core. This has executables and libraries that allow you to run this on windows.
  • sleuthkit-X.X.X-framework-win32.zip: This is the compiled windows release of the framework. It has the tsk_analyzeimg program that allows you to run the framework on a disk image.

For all packages, GPG signatures exist.

The Sleuth Kit can be used with Autopsy, which can be downloaded here. Autopsy 3 (Windows-only) does not require an explicit Sleuth Kit Installation. Autopsy 2 requires that The Sleuth Kit be installed first.

Refer to the SleuthKitWiki for Packages and Add-ons.

Bugs

See the Support page for details on reporting bugs.

Announcements

Announcements of new releases are sent to the sleuthkit-announce and sleuthkit-users e-mail lists and the RSS feed .